#VU126179 Stored cross-site scripting in Arista Edge Threat Management - Arista NG Firewall (NGFW) - CVE-2026-25624
Published: April 15, 2026
Arista Edge Threat Management - Arista NG Firewall (NGFW)
Arista Networks
Description
The vulnerability allows a remote user to execute arbitrary script in the administrator's browser.
The vulnerability exists due to cross-site scripting in an administrative interface when rendering crafted content in the NGFW user interface. A remote privileged user can inject crafted script to execute arbitrary script in the administrator's browser.